sweno Wrote:And it pains me to see such a promising project attempt to add on security like spackle over gaps in their foundation.
Actually, this is something that's bugging me about a lot of the comments on that post. Because, based on my understanding of the Rails framework, the right place to put the security checks wouldn't be in the code that's getting complained about *anyway*. If they make use of the tools, they will in essence be -doing it right-.
-Morgan.